Monthly Archive: September 2025

SAP Patches Critical Flaws Allowing Full System Takeover

SAP has addressed two critical vulnerabilities in the NetWeaver Java application server that could allow attackers to execute arbitrary code and fully compromise affected systems. The security updates, released in September 2025, remediate CVE-2025-42922...

VMScape: A New CPU Vulnerability Threatens Cloud Security

Researchers at ETH Zurich have unveiled a novel attack dubbed VMScape, bearing strong resemblance to Spectre and posing a significant threat to virtualization infrastructures. The attack enables a malicious virtual machine to extract cryptographic...